3 ms·
It just means that you are the owner of the data. If you want to have your data, you can download them at any time and share them with anyone you want. If you
by danielgomari 4y ago
It just means that you are the owner of the data.
If you want to have your data, you can download them at any time and share them with anyone you want.
If you want us to delete the data, we will do that.
If you don't say anything, we will never share your data with anyone.
- austinjp 4y agoIt would be more reassuring for you to explain exactly how you do use the data. Are you training neural networks, even with aggregated/anonymised data? Are you creating synthetic data? I'd be specifically interested in exactly how you "delete" data after the user requests this, and how you ensure that any data breach could not reveal identifying information. Perhaps HIPAA covers some or all of this, I'm not sure. But personally I'd want extremely detailed reassurance about these items.
- WaitWaitWha 4y agoI appreciate what you are trying to say (I think) but the way this is presented seems to contradict previous statement. > The resulting data is then securely sent over to us (we’re HIPAA compliant) So the material is considered and under the protection of HIPAA. > At no time shall your Personal Information, including blood or metabolomic data collected from you in accordance with this Privacy Policy be deemed to be an electronic health record or an electronic medical record for any purpose, including without limitation for the purpose of compliance with the Health Insurance Portability and Accountability Act of 1996. This reads like 'because we do not consider your data to be PHI, therefore it is not under HIPAA.' ergo, lose all HIPAA protection. Might want to re-write this if that is not what you meant.
- bearjaws 4y agoI've seen this literature used before, you can make such a claim if you are a transmitter of data, e.g. a SMS carrier. However this would certainly fall flat on its face if you were a actual EHR / EMR.
- danielgomari 4y agoThe legal language here can indeed be confusing. EHR and PHI are not the same thing. What is important is that your personal information will not be shared with anyone. We will make sure that the language on our webpage is more concise, thank you for pointing this out.
- hinkley 4y agoI also read that as “we can sell this data”. The thing you need to remember with consumer protection is that a failing company will abandon everything including ethics in order to pay the piper. Especially after they have laid you off. There’s a reason some capital E ethical companies put poison pills or time bombs in their charter. Booby traps of this sort actually instill trust in people who have heard a line of bullshit so often they can see it a mile away.
- ryanSrich 4y agoHIPAA only covers business associates, covered entities and subcontractors. I’m guessing this company is neither of those three. Therefore the “PHI” you provide to them, is not “PHI” under HIPAA since you are providing the data, and not a covered entity.
- chaostheory 4y agoThis is what I was looking for